在 Eleveo 呼叫录音软件 9.7.0 中发现了一个漏洞。该漏洞影响用户管理(User Management)组件中文件 /callrec/userAddAction.do 的未知代码。对参数 Username 的此类操纵会导致 LDAP 注入。该漏洞可以被远程利用。目前已有公开可用的漏洞利用代码,可能会被攻击者使用。厂商在披露早期已被联系,但并未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eleveo | Call Recording Software | 9.7.0 |
cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101142 | 6.3 MEDIUM | Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversal |
| CVE-2026-101144 | 6.3 MEDIUM | Eleveo Call Recording Software Query Builder searchAction.do access control |
| CVE-2026-101143 | 4.3 MEDIUM | Eleveo Quality Management QMBODownload information disclosure |
| CVE-2026-101146 | 4.3 MEDIUM | Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit informati |
| CVE-2026-101141 | 3.5 LOW | Eleveo Call Recording Software Play Audio audio.jsp cross site scripting |
No comments yet